You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Python递归删除Azure Data Lake Gen1的访问控制列表(ACL)?

Recursive ACL Removal for Azure Data Lake Storage Gen1 in Python

Absolutely, you can pull off recursive ACL removal for Azure Data Lake Storage Gen1 using Python—you just need to roll your own recursion logic since there’s no out-of-the-box remove_access_control_recursive method like the one available for Gen2. Let me walk you through how to do this step-by-step:

Prerequisites

First, install the required Python packages to interact with ADLS Gen1:

pip install azure-mgmt-datalake-store azure-identity

Example Implementation

This script will recursively traverse your target directory, remove the specified ACL entry from every file and subdirectory, and update the ACLs accordingly:

from azure.identity import DefaultAzureCredential
from azure.mgmt.datalake.store import DataLakeStoreAccountManagementClient

def remove_acl_recursively(account_name, root_path, acl_entry):
    # Initialize authentication and ADLS Gen1 client
    credential = DefaultAzureCredential()
    adls_client = DataLakeStoreAccountManagementClient(credential, "<your-subscription-id>")
    
    def process_single_path(path):
        try:
            # Fetch the current ACL for the target path
            current_acl = adls_client.adls_store.get_access_control(account_name, path)
            # Filter out the ACL entry we want to remove
            acl_lines = [line.strip() for line in current_acl.split('\n') if line.strip()]
            updated_acl_lines = [line for line in acl_lines if line != acl_entry.strip()]
            updated_acl = '\n'.join(updated_acl_lines)
            
            # Apply the cleaned-up ACL back to the path
            adls_client.adls_store.set_access_control(account_name, path, updated_acl)
            print(f"Successfully updated ACL for: {path}")
            
            # If this is a directory, process all child files/subdirectories
            file_status = adls_client.adls_store.get_file_status(account_name, path)
            if file_status.is_directory:
                child_items = adls_client.adls_store.list_file_system(account_name, path)
                for item in child_items:
                    # Handle root path vs subdirectories to avoid malformed paths
                    child_path = f"{path}/{item.name}" if path != '/' else f"/{item.name}"
                    process_single_path(child_path)
                    
        except Exception as e:
            print(f"Failed to process {path}: {str(e)}")
    
    # Start the recursive processing from your root directory
    process_single_path(root_path)

# Usage example
if __name__ == "__main__":
    # Replace with your ADLS Gen1 account details
    ADLS_ACCOUNT = "your-adls-gen1-account-name"
    TARGET_DIRECTORY = "/my-parent-directory"
    # Specify the ACL entry to remove (add "default:" prefix for default scope entries)
    ACL_ENTRY_TO_REMOVE = "user:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
    # For default scope: "default:user:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
    
    remove_acl_recursively(ADLS_ACCOUNT, TARGET_DIRECTORY, ACL_ENTRY_TO_REMOVE)

Key Notes

  • Manual Recursion: Since Gen1 doesn’t have a built-in recursive ACL method, we explicitly traverse every file and subdirectory to update permissions one by one.
  • Permissions Check: Make sure the identity running the script has sufficient ACL permissions (at minimum, Write and Execute on all paths being modified) to make changes.
  • ACL Entry Precision: Match the exact format of the ACL entry you want to remove. For default scope entries, include the default: prefix (e.g., default:user:<object-id>).
  • Error Resilience: The script includes basic error handling to catch issues with individual paths without stopping the entire recursive operation.

内容的提问来源于stack exchange,提问作者Ash3060

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 14:42:45